CVE-2026-21310: Adobe Commerce | Improper Input Validation (CWE-20)
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass, with limited impact to integrity. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21310?
The severity of CVE-2026-21310 is considered moderate due to its potential for security feature bypass.
How do I fix CVE-2026-21310?
To fix CVE-2026-21310, users should update Adobe Commerce to the latest version provided by Adobe.
What versions are affected by CVE-2026-21310?
CVE-2026-21310 affects Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, and earlier.
What kind of vulnerability is CVE-2026-21310?
CVE-2026-21310 is classified as an Improper Input Validation vulnerability that may lead to security feature bypass.
Is CVE-2026-21310 exploitable remotely?
Yes, CVE-2026-21310 can be exploited remotely, making it critical for affected systems to be addressed promptly.